SDBot Remote Access Trojan
SDBot is a newly observed C-- based remote access trojan created by the TA505 advanced persistent threat group for use in their campaigns.
Summary
SDBot is a newly observed C-- based remote access trojan created by the TA505 advanced persistent threat group for use in their campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
As SDBot is a second stage payload, it is reliant on TA505's other tools for its delivery. At the time of publication, only the Get2 loader has been observed distributing SDBot, although it is likely other tools such as ServHelper and AndroMut may be used in future campaigns.
Once installed, SDBot uses application shimming (ATT&CK T1138) to escalate its privileges before disabling security services. It will then connect to a command and control sever over TCP port 443 to await further commands. By default, SDBot has the following capabilities:
- launch a command shell
- create remote desktop sessions
- extract files
- download and install further payloads
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect a trojan infection, ensure that:
|
Last edited: 11 January 2022 1:34 pm